AdminARK — Terms of Service

Effective date: September 1, 2025

Company: AdminARK, a company organized under the laws of British Columbia, Canada ("AdminARK", "we", "us", "our").

Contact: support@adminark.com

1) Agreement & Scope

By creating an account, onboarding a business, or using our Services, you agree to these Terms of Service ("Terms") and our Privacy Policy (together, the "Agreement"). If you use the Services on behalf of an organization, you represent you have authority to bind that organization; "Customer," "you," and "your" include that organization.

"Services" means our B2B SaaS for document and project workflows (including uploads, storage, search, document generation, e-signature routing, optional AI analytics/search, email sending/integrations, and calendar integrations), plus related websites, apps, and APIs.

2) Accounts, Business Onboarding & Eligibility

  • Eligibility. You must be the age of majority where you live to use the Services.
  • Business Scope. Users join or create a Business during onboarding. Access and data are scoped by business_id; database row-level security (RLS) enforces this separation.
  • Credentials. You are responsible for safeguarding credentials and all activity under your account. Notify us promptly of unauthorized use.

3) Plans, Seats, Limits & Fair Use

  • Plans. We offer plan tiers (e.g., Starter, Professional, Team, Enterprise) with different features/limits shown at checkout or on our pricing page.
  • Seats. A Seat is a named user license; Seats aren’t shared or used concurrently by multiple people.
  • Limits & Rate-limits. We may enforce plan limits and apply rate limiting or circuit breakers to protect stability and security.
  • Changes. We may modify plan features/limits with reasonable notice; material adverse changes will be communicated where practicable.

4) Fees, Taxes, Billing & Renewals

  • Fees & Taxes. You agree to pay all fees plus applicable GST/HST/PST and other taxes.
  • Auto-Renewal. Subscriptions renew unless you cancel before renewal.
  • Payment. You authorize us and our payment processor to charge your payment method when due.
  • Refunds. Except where required by law or expressly stated, fees are non-refundable.
  • Late/Overage. We may charge reasonable late fees and bill overages beyond plan limits.

5) What the Services Provide (High Level)

  • Documents: upload, store, view, search, export (PDF/Excel/ZIP), version comments/approvals, link to projects.
  • Document Generator & PDF Viewer/Editor: PDF worker may be served publicly; secure proxy enforces business checks, CORS allowlists, secure headers, rate limits, and supports Range requests.
  • E-Signature (OneSpan): sessions, package actions, webhooks, signed downloads.
  • Projects & Contacts: project activity logs; document linking; contacts, notes, tasks, assignees; import/export.
  • Email: Send via SendGrid; optionally connect Gmail OAuth or custom SMTP per business/user.
  • Calendar: Google Calendar OAuth to list calendars and events per user.
  • AI (DocuIntelligence/analytics): optional, user-triggered analysis (OpenAI; Anthropic SDK present but not required) for enhanced search and analysis.
  • Global Search & Health; Admin/Compliance: consent records; GDPR/DSR export and account-deletion flows.

6) Customer Data, Ownership & License

You own Customer Data. You grant us a limited license to host, process, and transmit Customer Data solely to provide and improve the Services and comply with law. You have all rights to submit Customer Data and maintain lawful bases for personal information.

7) Data Protection & Privacy

We act as processor for workspace data and controller for account/billing/telemetry. Tools: consent logging, export via signed URLs, account deletion with explicit confirmation and sole-member handling. Security measures include RLS, secure proxy, HSTS, CSP, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, COEP/CORP, rate-limiting, circuit breakers, auditing. See Privacy Policy and DPA.

8) Optional AI Features

AI is opt-in only. Providers: OpenAI (and potentially Anthropic). Outputs are probabilistic; review required; no high-risk use. No provider training by default; any training would be opt-in.

9) Third-Party Services & Subprocessors

Feature-dependent: Supabase (auth, DB, storage); OpenAI (AI); SendGrid (email); Google (OAuth Calendar/Gmail); OneSpan (e-signature). See Privacy Policy or subprocessors page for updates.

10) E-Signature (OneSpan)

You are responsible for routed content and signers. We do not provide legal validity opinions. Signed artifacts are available to download; ongoing retention is your responsibility unless agreed.

11) Email & Calendar Integrations

You must comply with CASL and obtain required consents. Calendar access is per user; tokens can be disconnected.

12) Acceptable Use

No unlawful content/malware/infringement; no bypassing security/RLS; no scraping beyond documented endpoints/rate limits; no high-risk uses; comply with CASL; do not resell Seats; do not access other businesses’ data.

13) Intellectual Property; Feedback

We and our licensors own the Services and related IP (excluding Customer Data). You receive a limited license to use the Services; feedback may be used to improve the Services.

14) Confidentiality

Confidential Information is protected and used only to perform under these Terms; standard exclusions apply.

15) Availability, Changes & Support

We may modify features/limits with reasonable notice; no guarantee of uninterrupted or error-free operation. Formal SLAs apply only if explicitly agreed.

16) Beta/Preview Features

Provided as-is, excluded from SLAs and warranties.

17) Warranties & Disclaimers

THE SERVICES ARE PROVIDED ON AN "AS IS" AND "AS AVAILABLE" BASIS. TO THE MAXIMUM EXTENT PERMITTED BY LAW, ADMINARK DISCLAIMS ALL WARRANTIES, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING WITHOUT LIMITATION ANY WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, OR THAT THE SERVICES WILL BE ERROR-FREE OR UNINTERRUPTED. ADMINARK MAKES NO REPRESENTATION OR WARRANTY REGARDING THE ACCURACY, RELIABILITY, OR UTILITY OF ANY OUTPUT PRODUCED THROUGH ARTIFICIAL INTELLIGENCE OR AUTOMATED TOOLS. ALL DECISIONS BASED ON SUCH OUTPUT ARE SOLELY THE RESPONSIBILITY OF THE USER.

18) Indemnities

You agree to indemnify, defend, and hold harmless AdminARK, its affiliates, officers, employees, and agents from and against any and all claims, liabilities, damages, losses, and expenses (including reasonable legal fees) arising out of or in any way connected with: (i) your use of the Services; (ii) your violation of these Terms; (iii) your uploaded or processed data, including any third-party claims of infringement, misappropriation, or violation of privacy; or (iv) reliance by you or third parties on outputs generated by the Services. Standard notice, control, and cooperation terms apply.

19) Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW, ADMINARK AND ITS AFFILIATES, DIRECTORS, OFFICERS, EMPLOYEES, AND SUBPROCESSORS SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, INCLUDING BUT NOT LIMITED TO LOSS OF PROFITS, DATA, OR BUSINESS OPPORTUNITIES, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. ADMINARK’S TOTAL LIABILITY ARISING OUT OF OR RELATING TO THE SERVICES SHALL NOT EXCEED THE GREATER OF: (I) THE FEES PAID BY CUSTOMER TO ADMINARK IN THE TWELVE (12) MONTHS PRECEDING THE CLAIM, OR (II) CAD $500. NOTHING IN THIS AGREEMENT SHALL LIMIT LIABILITY FOR FRAUD, GROSS NEGLIGENCE, OR WILLFUL MISCONDUCT.

20) Term, Suspension & Termination

We may suspend for AUP/security/legal reasons or non-payment. Termination for uncured material breach or your cancellation. Export data before termination.

21) Compliance; Export; Anti-Corruption

Comply with applicable laws (privacy, CASL, IP, export/sanctions). No prohibited jurisdictions/end uses.

22) Publicity

We may use your name/logo for customer identification unless you opt out by notice to support@adminark.com.

23) Assignment

You may not assign without consent except in connection with a corporate transaction. We may assign to an affiliate/successor.

24) Notices

We may notify via UI or email. You will send notices to support@adminark.com.

25) Changes to These Terms

We may update Terms; material changes notified via Services or email; continued use after effective date constitutes acceptance.

26) Governing Law & Venue

This Agreement shall be governed by and construed under the laws of the Province of British Columbia and the federal laws of Canada applicable therein, without regard to conflicts of law principles. Any dispute shall be resolved exclusively in the courts located in Vancouver, British Columbia. The parties waive any right to trial by jury and any right to participate in class actions or representative proceedings.

27) General

Severability, no implied waivers, entire agreement including applicable order forms, SLA, and DPA.

Exhibit A – Subprocessors (Feature-Dependent)

Supabase (auth, database, storage) • OpenAI (AI processing when invoked) • SendGrid (email delivery) • Google (OAuth for Calendar/Gmail; calendar metadata/events; optional Gmail send) • OneSpan (e-signature workflow and signed files). See Privacy Policy for updates.

Exhibit B – Security Overview (Summary)

Auth: Supabase Auth (JWT) with business-scoped RLS • Storage via secure proxy (business checks, rate limits, CORS allowlist, secure headers, Range) • Headers/CSP: HSTS, CSP, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, COEP/CORP, powered-by disabled • Controls: enterprise rate limiting, circuit breakers, draft visibility, consent logging • Monitoring: in-app error/performance monitoring.

Exhibit C – Data Subject Rights & Retention

Consent logs • Self-service export via expiring signed URL • Account deletion with explicit confirmation (sole-member business handling) • No fixed automated retention in code; data persists until deleted by you or as required by law.

Exhibit D – Acceptable Use (Detailed)

No unlawful content/malware/infringement • No bypassing RLS or accessing other businesses’ data • No scraping beyond documented endpoints/rate limits • No high-risk/life-critical uses • Comply with CASL for all emails (SendGrid, Gmail OAuth, custom SMTP) • Respect terms for Google, OneSpan, OpenAI, SendGrid, and any other integrations you enable • Review AI outputs before critical use.

Security and Data Incidents

AdminARK employs industry-standard administrative, technical, and physical safeguards to protect Customer Data. Customer acknowledges, however, that no system is impenetrable. In the event of a confirmed Security Incident affecting Customer Data, AdminARK will notify affected Customers without undue delay, consistent with applicable law. Such notice shall not be construed as an admission of fault or liability.

Survival

The provisions concerning disclaimers, limitations of liability, indemnification, confidentiality, intellectual property, governing law, and dispute resolution shall survive termination of your account or this Agreement.